# Payco — security contact (RFC 9116) # # This file is deliberately boring. It exists so that somebody who finds a flaw in payco.ai has # an unambiguous place to send it, instead of guessing at an inbox or posting it publicly. It # names ONLY addresses that already exist and are already published on this site — inventing a # security@ alias that nobody has created would bounce the one report that mattered, which is # strictly worse than having no file at all. # # Expires is required by RFC 9116 and is not decoration: a stale security.txt tells a finder the # contact is unmaintained. Renew this date, and re-check the address below still reaches a human, # before it passes. # # Policy was the one RFC 9116 field this file was missing, and it was missing for the same reason # the Contact list is short: there was no published disclosure policy to point at, and naming a # URL that 404s is worse than omitting the field. /vulnerability-disclosure now exists — it states # what is in scope, the response times we commit to, and the safe harbour — so the field is real. # If that page is ever removed, remove this line in the same commit. Contact: mailto:support@mypayco.com Contact: tel:+1-424-230-7212 Expires: 2027-07-29T00:00:00.000Z Preferred-Languages: en Canonical: https://payco.ai/.well-known/security.txt Policy: https://payco.ai/vulnerability-disclosure